AI Providers Have De Facto Regulation in Europe Since This Morning; Meta Is the Main Absence

The European Commission's AI Office has assumed formal powers to oversee and fine general-purpose AI (GPAI) providers as of this Sunday. Meta is the only major Western company to refuse the Code of Good Practices.
The European Commission's AI Office has formally assumed oversight powers over providers of general-purpose artificial intelligence (GPAI) models operating in the European market as of this Sunday. The authority includes the ability to summon companies, conduct independent technical evaluations of models, require compliance measures, and impose fines of up to €15 million or 3% of global annual revenue, whichever is higher. The date is not a surprise to the sector, but its arrival marks the end of the period during which the world's largest model providers operated in the EU without binding oversight.
OpenAI, Anthropic, Google DeepMind, Microsoft, and Mistral are among the providers most directly affected. All have signed the Code of Good Practices for GPAI by 2025, providing them with a presumption of compliance during the transition period. Over twenty organizations are part of the Code, including Amazon, IBM, and the German Aleph Alpha. Companies based in China were left out.
The New Competencies of the AI Office
The powers formalized this Sunday cover four axes: requesting technical documentation and information about the models; conducting independent technical assessments of the systems; demanding risk mitigation measures or the withdrawal of the model from the European market; and applying financial sanctions. Providers who fail to meet transparency obligations, such as maintaining documentation on the training process and providing summaries of the data used, will be exposed to these sanctions in the upcoming oversight rounds. The obligation to comply with copyright rules when using training data is also now formally enforceable.
For models that exceed the systemic risk threshold, defined as systems trained with more than 10^25 FLOPs of computation, the obligations are stricter: assessment prior to the launch of new versions and mandatory notification to the Office in the event of serious incidents. This threshold encompasses the latest generations of OpenAI's GPT, Google’s Gemini Ultra models, and Anthropic's Claude 4 series.
Meta: The Riskier Bet
Joel Kaplan, head of global affairs at Meta, stated in 2025, when announcing the company's refusal to adhere to the Code, that "Europe is on the wrong path in AI." Meta argued that the Code introduces legal uncertainties and imposes obligations beyond what the text of the AI Act provides. The company is not the only one absent from the Code, but it is the only major Western platform with a significant presence in the European market to opt out.
The Code of Good Practices offers its signatories a good faith clause: the AI Office tends to treat those who have adhered to prior commitments as cooperative actors in any sanctioning process. Without this protection, Meta approaches August 2026 as the only major Western company exposed to an oversight regime without the buffer of documented prior compliance.
This risk also extends to those using the company’s products. European organizations deploying Llama as a basis for agents and assistants cannot rely on the provider's compliance. Each Llama deployment in European environments requires the responsible company to ensure, on its own, that the implementation meets the transparency and documentation requirements of the AI Act. The absence of a signed Code of Practice by the provider does not exempt the deployer.
What Is Yet to Come into Effect
The so-called AI Act Omnibus, approved by the European Parliament in May 2026, consolidated deadlines for high-risk AI systems: the obligations for autonomous systems listed in Annex III will take effect on December 2, 2027, and for AI systems embedded in regulated products (Annex I), on August 2, 2028. Transparency rules for conversational interfaces with end users, such as the obligation to inform that the interaction is with AI, have been in effect since August 2025.
For CIOs and CSOs managing contracts with model providers in the EU: your suppliers' general-purpose AI systems are now under formal oversight as of today. The high-risk AI systems that the organization operates internally, such as automated credit tools or personnel screening, have compliance deadlines extending to 2027 and 2028. But discussions with model providers begin now.
The First Real Test Awaits
No company has been investigated so far. Providers who are signatories to the Code have an interest in making this learning curve cooperative: the first 3% global revenue fine against one of the major AI companies will transform the European political debate on technology into something much more concrete, and, for non-signatories, much more urgent.
Meta, without the protection of the Code, is the only major Western company betting that the cost of resistance is less than the cost of compliance. As of today, that bet has become more expensive.